Key Takeaways
- Hackers drained $387.5 million from cryptocurrency platform Bitget on Sept. 24.
- NEAR Intents reports its SHIELD security framework successfully prevented over $50 million in illicit fund transfers related to the breach.
- A previously unknown vulnerability in third-party security software allowed the hacker to obtain administrator privileges before erasing attack evidence.
- The exchange’s $465 million user protection reserve will compensate all losses, with plans to replenish it to $300 million minimum within seven days.
- Decentralized protocol THORChain rejected requests to blacklist addresses associated with the perpetrator, citing its non-censorship policy.
Cryptocurrency trading platform Bitget suffered a devastating security breach Thursday resulting in the theft of $387.5 million. The perpetrator rapidly distributed the stolen assets across multiple blockchain networks within hours of the initial compromise.
NEAR Intents, a cross-chain asset exchange protocol, reports successfully preventing a significant portion of the pilfered funds from being laundered. According to general manager Alex Shevchenko, the platform’s SHIELD security infrastructure identified and halted over $50 million in transfer attempts linked to the security incident.
Shevchenko disclosed that the system successfully immobilized $503,000 during transit. However, approximately $166,000 in potentially stolen cryptocurrency evaded detection.
Anatomy of the Bitget Security Breach
Bitget’s CEO Gracy Chen provided a detailed chronology of the attack during a conversation with The Block. According to Chen, the perpetrator initiated two preliminary test transactions at 6:31 p.m. UTC on Sept. 24.
These initial transfers consisted of 0.184 ETH and 193 TRX. Both amounts fell below Bitget’s risk detection thresholds, allowing them to process without triggering security alerts.
Approximately half an hour later, the hacker executed substantially larger withdrawals. Chen revealed that 17 separate transactions spanning eight distinct networks—Ethereum, XRP, Zcash, BNB Chain, Base, Arbitrum, Optimism, and Avalanche—collectively totaled approximately $361 million.
The exchange’s response was swift. Its reconciliation infrastructure detected discrepancies just seven minutes following the first major withdrawal, prompting Bitget to immediately suspend all customer withdrawals across the entire platform.
By that point, the perpetrator had already compromised an internal administrative interface. Chen explained that the intruder leveraged an undisclosed zero-day vulnerability in external security software to acquire legitimate administrator credentials.
This elevated access enabled the attacker to inject fraudulent withdrawal requests into Bitget’s wallet infrastructure, which processed them as legitimate transactions. The perpetrator subsequently erased digital forensic evidence, which Chen described as the most challenging aspect of the investigation.
According to Bitget, private keys and cold storage facilities remained uncompromised. The organization is collaborating with cybersecurity firms Mandiant and SlowMist and intends to publish a comprehensive incident analysis later this week.
While Chen declined to identify potential suspects, she indicated that Bitget suspects the same organization responsible for multiple recent cryptocurrency heists.
Contrasting Responses from NEAR Intents and THORChain
This security incident has reignited discussion regarding how permissionless cryptocurrency protocols should address stolen assets. Chen requested that THORChain, a decentralized exchange protocol, blacklist wallet addresses connected to the perpetrator.
THORChain refused the request. The protocol stated it does not implement selective transaction censorship, although it has previously suspended network operations during critical emergencies.
NEAR Intents adopted a contrasting approach. Shevchenko confirmed his platform will proactively prevent stolen cryptocurrency from transiting through its infrastructure.
He additionally announced that NEAR Intents will forgo the 5% bounty Bitget offered for freezing assets, along with an additional 5% for recovery, enabling maximum funds to return to the exchange. Separately, stablecoin issuers Circle and Tether froze a wallet connected to the perpetrator on Friday, restricting access to $318,013 in USDT and USDC.
As of Sept. 25, Bitget’s protection fund maintained a balance of $465 million and will cover all losses. Chen stated that corporate reserves exceeding $1.4 billion will restore the fund to a minimum of $300 million within seven days.
Bitcoin withdrawal functionality on Bitget resumed Monday, processing over 3,000 BTC during the initial hour. Ethereum withdrawals are scheduled to reopen Sept. 29.



